Google Docs OfflineSecurity Analysis

Chromev1.100.1MV3February 16, 2026 at 01:13 PM
6.7HIGH
6.7 HIGH

This extension shows significant risk signals. Review the findings below carefully before installing or continuing to use it.

Based on 6 permissions including high-risk ones, 13 code findings.

Permissions
6.5/10
Code
8.9/10
Combinations
0.0/10
Manifest/CSP
6.3/10

Permissions(6 analyzed)

Code Findings(7 patterns, 13 total)

Content Security Policy

CSP Present(1 issue)
LOW
object-srcobject-src not restricted

object-src is not set to 'none'. Plugins like Flash can be embedded, which may allow code execution.

Manifest Analysis(3 findings)

Resolved from __MSG_* i18n placeholders:

Name: Google Docs Offline

Description: Edit, create, and view your documents, spreadsheets, and presentations — all without internet access.

HIGH
web_accessible_resourcesJS files exposed to web pages

JavaScript files are accessible to ALL websites. Any page can load and interact with these scripts, enabling web→extension attacks.

MEDIUM
web_accessible_resources.matchesOverly broad match patterns

Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.

LOW
externally_connectableExternal messaging enabled

Extension accepts messages from 12 external pattern(s). Verify these are trusted origins.

External Domains(3)

meetwww.broofa.comwww.gstatic.com

Indicators of Compromise

4 indicators of compromise found

File Statistics

88
Total Files
3
JS Files
380.0 KB
Total Size

Other Scanned Extensions